First published: Mon Jun 08 2009(Updated: )
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dokuwiki Dokuwiki | =rc2009-02-06 | |
Dokuwiki Dokuwiki | =2009-02-14 | |
Dokuwiki Dokuwiki | =rc2009-01-30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.